Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-14428 confirms this npm version as malicious. consumerweb-serverutils 3.4.3 runs a preinstall lifecycle script that on npm install collects the installer's username, hostname, and current working directory, walks up the directory tree to read the enclosing project's package.json (name, author, version), hex-encodes the aggregated JSON, splits it into 60-character chunks, and exfiltrates it as DNS label queries to the attacker-controlled zone o.jgl.red (observed...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg